A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HRed Hat OpenShift Container Platform
APPRedhat3.103.11
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
Related vulnerabilities
CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓same product
RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu
CVE-2019-1003030CRITICAL9.9⚠ KEVPL ✓same product
Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)
CVE-2019-1003029CRITICAL9.9⚠ KEVPL ✓same product
Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE
CVE-2018-1000861CRITICAL9.8⚠ KEVPL ✓same product
RCE w Jenkins — nieuprawnione wywołanie metod przez Stapler framework
CVE-2026-4408CRITICAL9.0PL ✓same product
Samba: RCE przez command injection w 'check password script' z podstawieniem %u